Non-profit

Non-profit organization data breaches expose donor financial information, employee and volunteer personal records, and sometimes sensitive data about the individuals a non-profit serves, such as clients of a healthcare, housing, or social services organization. These exposures can lead to identity theft, direct financial fraud, and scams that specifically target donors using stolen names, giving histories, and contact information to impersonate the organization or solicit further payments. Non-profits are frequently under-resourced when it comes to cybersecurity relative to the amount and sensitivity of the data they collect, which can make them attractive targets despite operating on limited budgets. Depending on the organization’s mission, a breach may also expose especially sensitive information about vulnerable populations the non-profit serves, raising additional privacy concerns beyond typical financial data. This page tracks confirmed data breaches at non-profit organizations, including what data was exposed, which companies notified regulators, and what affected individuals can do next to protect themselves.

Methodist Homes of Alabama & Northwest Florida Data Breach

A senior man and caregiver engage in a meaningful conversation at home.

Methodist Homes of Alabama & Northwest Florida discovered unauthorized network access between October 2 and October 14, 2024, later confirming on September 2, 2025, that hackers may have accessed patients', residents', and non-residents' names, Social Security numbers, driver's license numbers, health insurance details, and medical records. Affected individuals should immediately place a fraud alert or

Methodist Homes of Alabama & Northwest Florida Data Breach Read More »

UFCW Local No. 7 Data Privacy Incident: Immediate Steps You Can Take

UFCW Local No. 7 Data Privacy Incident: Immediate Steps You Can Take

UFCW Local No. 7 discovered suspicious network activity on December 11, 2024, later determining an unauthorized actor accessed files on December 10, 2024, containing members' names and Social Security numbers. No financial or payment card data was exposed. Confirmed on August 21, 2025, this affects union members whose personal information was stored in the compromised

UFCW Local No. 7 Data Privacy Incident: Immediate Steps You Can Take Read More »